Threat Advisory

ContextForge Flaw Lets Attackers Bypass SSRF Protection

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-53708 is a Server-Side Request Forgery vulnerability in ContextForge's gateway management API, allowing an attacker to bypass SSRF protection via DNS rebinding. The attack requires a credential with explicit gateways.read permission assigned via a database role and occurs when the attacker controls DNS for a hostname that resolves to a public IP during validation but a private IP at connection time. This vulnerability affects versions prior to 1.0.3, enabling an attacker to probe internal network services, retrieve cloud credentials from instance metadata, access internal APIs not exposed to the internet, or conduct port scanning of the internal network. The attack exploits a TOCTOU window between DNS validation and HTTP client resolution, where the validated IP address is never passed to the client, and only the original hostname is forwarded for re-resolution. This vulnerability has a CVSS score of 6.6 and affects ContextForge's gateway management API, which requires a database-backed role assignment with gateways.read permission for an attacker to successfully exploit it.

RECOMMENDATION:

We recommend you to update mcp-contextforge-gateway to version 1.0.3.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-53708 is a Server-Side Request Forgery vulnerability in ContextForge's gateway management API, allowing an attacker to bypass SSRF protection via DNS rebinding. The attack requires a credential with explicit gateways.read permission assigned via a database role and occurs when the attacker controls DNS for a hostname that resolves to a public IP during validation but a private IP at connection time. This vulnerability affects versions prior to 1.0.3, enabling an attacker to probe internal network services, retrieve cloud credentials from instance metadata, access internal APIs not exposed to the internet, or conduct port scanning of the internal network. The attack exploits a TOCTOU window between DNS validation and HTTP client resolution, where the validated IP address is never passed to the client, and only the original hostname is forwarded for re-resolution. This vulnerability has a CVSS score of 6.6 and affects ContextForge's gateway management API, which requires a database-backed role assignment with gateways.read permission for an attacker to successfully exploit it.

RECOMMENDATION:

We recommend you to update mcp-contextforge-gateway to version 1.0.3.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu